Freedam
GuidesPart 3 of 4 · 10 min read

Shared links, rights and the audit trail: what a drive does not record

A brand manager is asked whether the company can reuse a 2023 campaign photograph for a new landing page. The file is in the shared drive. She can open it, download it, and send it to anyone. What she cannot do is answer the question.

Who shot it. Whether it was a commissioned shoot or a stock licence. If stock, which licence, and whether it covered web use, and whether it has expired. Whether the people in it signed a release, and whether that release covered a use like this one. Whether legal put a hold on it after the 2024 rebrand.

A shared drive answers "can this person open this file". That is access control, and Google and Dropbox both do it competently. Rights management answers a different question: "may we use this picture, for this purpose, in this market, today". No drive records the information that question needs, because no drive has fields to put it in.

This is part 3 of a four-part series. Part 1 covers the published limits, part 2 covers why file search cannot find an image, and part 4 covers migration.

Nothing here is legal advice. It is a description of what the tools record.

What the sharing controls actually do

It is worth being accurate about this, because the vendor comparison genre tends to imply that cloud storage has no controls at all. It does.

Google Drive lets a file owner set an expiration on access for a named person. Google's sharing documentation describes the flow: open Share, click the arrow next to the person's name, add an expiration, and "Choose a date within one year of the current date". The feature is available on eligible work and school accounts.

Two properties of that mechanism matter. It applies to people you have named individually, not to a shared link. And the ceiling is one year, which is shorter than most stock licences and shorter than most brand campaigns.

Dropbox goes further on links. On Professional, Essentials, Standard, Advanced, Business, Business Plus and Enterprise plans, a shared link can carry an expiry date and a password, the link is disabled at 11:59pm on the chosen day, and an admin can set a default expiration for every link the team creates. This is a genuinely good control and it is better than what most DAM buyers assume cloud storage offers.

Both are controls over access. Neither is a record of permission. The distinction is the whole subject of this guide: a link that expires stops someone opening the file. It says nothing about whether the file was ever cleared for the use they had in mind, and it does not travel with the copy they already downloaded.

What a rights record has to contain

The photography industry settled this question decades ago, and the answer is in the IPTC Photo Metadata Standard: Creator, Credit Line, Copyright Notice, Rights Usage Terms. Professional deliveries arrive with these fields filled in. As part 2 describes, nothing in Drive or Dropbox reads them.

A working rights record needs more than the file carries, because rights are a relationship between an asset and a use:

Field The question it answers
Source and licence type Commissioned, stock, user-generated, employee-shot, AI-generated
Licence holder and reference Which contract or invoice this traces to
Term From when, until when
Territory Which markets
Channels Print, web, paid social, out of home, packaging, internal only
Exclusivity Whether a competitor may also be using it
Model release Which people, which release document, which uses it covers
Property release Buildings, artworks, logos and trademarks visible in the frame
Restrictions Free text for the condition nobody anticipated

Six of those nine change over time or vary by use. That is why a folder called approved does not work: it encodes one bit of a nine-field answer, and it encodes it as of the day someone dragged the file in.

The concepts have entries in the glossary: usage rights and digital rights management.

Expiry as a mechanism, not a reminder

The common failure is not that nobody knows a licence expires. It is that knowing lives in one person's calendar.

A stock licence runs out on 31 March. The image is on the website, in a PDF brochure on the website, in a partner's microsite, in an email template that still sends, and in three decks that circulate. On 1 April every one of those is an unlicensed use, and the company finds out when an invoice arrives from an image-rights enforcement agency.

An embargo is the same mechanism pointed the other way: a product shot that must not appear before a launch date, in the library so people can prepare, and not downloadable until the date passes.

The difference between a mechanism and a reminder is what happens when nobody is looking. A reminder fires into an inbox. A mechanism makes the asset unavailable, revokes the shares that pointed at it, and can tell you where it had already been sent so those uses can be pulled. That last part requires a record of where it went, which is the next section.

Any library of event, staff, customer or influencer photography contains personal data. Under the GDPR and comparable regimes, the people in those photographs have rights over it, including the right to withdraw consent.

Three practical requirements follow, and none of them is met by a folder.

The consent has to be linked to the asset. A signed release in a filing cabinet, or a PDF in a different folder, does not answer "may we publish this photograph" at the moment someone is about to publish it. The release reference belongs on the asset record.

You have to be able to find every photograph of one person. When somebody withdraws consent, the obligation is not limited to the pictures you remember. It covers every frame they appear in, including the ones from a shoot nobody tagged. This is the practical argument for face recognition search in an internal library: the capability that makes person search convenient is the same capability that makes a withdrawal request answerable.

That capability has its own consequences, and they belong in the same conversation. A system that can identify people needs a lawful basis, a retention policy, and a way to switch it off per person. The engineering write-up on person search describes how the matching works.

You have to be able to show what you did. Which brings us to the log.

The audit trail

Google Workspace does record Drive activity. The Drive log events documentation lists what is captured: view, download, edit, create, delete, print, share, copy, upload, rename. That is a reasonable event set.

Three limits are documented on the same pages and are worth knowing before you rely on it.

Retention is six months. Google's data retention page gives Drive log events a six month window. Rights disputes, licence audits and consent requests routinely reach back further than that. A photograph used in 2024 and challenged in 2026 has no log left.

Coverage is incomplete. Google states plainly that "not all activities in Drive are logged", with documented exclusions including print events on native Google formats and certain download routes.

Searching it well needs an upper plan. The security investigation tool, which is how you actually query across these events, is listed as available on Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus, and Cloud Identity Premium. A team on Business Standard has a different and more limited view of the same data.

Dropbox has a comparable activity log in the admin console, with sharing detail including whether a link had a password and when it expires.

Even a complete log has a structural gap for this purpose. It records file events: this account downloaded that file at that time. What a rights question needs is asset usage: this photograph appeared on that page, in that campaign, in that market, between those dates. Those are different records. The first can be reconstructed into the second only if somebody kept notes, which is to say only if somebody did the work the system was supposed to do.

The audit trail glossary entry sets out what the record has to contain to be usable after the fact: who, what, when, which version, under which permission, and for what stated purpose.

What a media library adds

Not a longer list of features. Three structural differences.

Rights live on the asset, not in a folder name. Every rendition, every crop, every share of that asset inherits them, because there is one asset record rather than eleven files.

Expiry and embargo are enforced by the system. When the term ends, the asset leaves the library's approved set, the share links pointing at it stop working, and the people who downloaded it can be identified from the record rather than from memory.

The trail is kept for as long as the exposure lasts, not for six months, and it is attached to the asset so that "show me everything that happened to this photograph" is one query rather than a log reconstruction.

Two related mechanisms are worth naming. Watermarking applies to previews and to external shares, so an unlicensed copy is visibly a preview. Access control governs who sees an asset at all, which is a separate concern from what they may do with it once they can.

Five checks on your current library

Run these against the drive you have. Each one takes a few minutes and the answers are usually uncomfortable.

  1. Pick a photograph published in the last two years. Find, without asking anyone, whether it was commissioned or licensed, and under what terms.
  2. Pick a stock image. Find its licence expiry date. Note where that date is recorded.
  3. Pick a photograph containing an identifiable person who is not an employee. Find their release.
  4. Ask who downloaded a specific file eighteen months ago. Check whether the log still has it.
  5. Take a person's name and find every photograph they appear in, including untagged ones.

If a check requires a colleague's memory, that memory is the system of record, and it leaves when they do.

Frequently asked questions

Can you set an expiry date on a Google Drive file?

You can set an expiration on a named person's access, from the Share dialog, and Google's documentation requires "a date within one year of the current date". It applies to individuals you have added, not to a shared link. Dropbox does support per-link expiry and passwords on its paid plans, and admins can set a team-wide default.

Does Google Drive log who downloaded a file?

Drive log events record downloads, along with view, share, print, copy, edit, delete, upload and rename. Retention is six months, Google states that not all Drive activities are logged, and querying across events with the security investigation tool requires Enterprise Standard or Plus, Frontline Standard or Plus, Education Standard or Plus, Enterprise Essentials Plus, or Cloud Identity Premium.

How do you track image usage rights?

On the asset record, not in a folder name or a spreadsheet. The fields that matter are source and licence type, licence reference, term, territory, permitted channels, exclusivity, model and property releases, and free-text restrictions. Six of those change over time, which is why a static folder called approved cannot represent them.

What happens when a stock licence expires?

Legally, every live use becomes unlicensed: the website, the PDFs on the website, partner microsites, scheduled emails, decks in circulation. Practically, most organisations discover it when an enforcement agency invoices them. A system with an expiry mechanism removes the asset from the approved set on the date, disables the shares pointing at it, and can list where it had already been sent.

Photographs of identifiable people are personal data under the GDPR and comparable regimes, so consent and its withdrawal have to be handled. The two operational requirements are that the release is linked to the asset rather than filed separately, and that you can find every photograph a given person appears in, including frames nobody tagged.

It is enough to control who opens the file. It is not a record of what they were permitted to do with it, it does not expire the copy they downloaded, and it carries none of the rights information forward. For external distribution, a brand portal with per-asset rights, download presets and a usage record answers questions a link cannot.


Next in the series: Moving off the shared drive. Previous: why you cannot find the image.

Keep reading